Trojan

Trojan-Banker.Win32.ClipBanker.gyp removal guide

Malware Removal

The Trojan-Banker.Win32.ClipBanker.gyp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Banker.Win32.ClipBanker.gyp virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Banker.Win32.ClipBanker.gyp?


File Info:

crc32: 1A29D1B8
md5: 94472427c06fe8a51e0f4a577d188397
name: setup_c.exe
sha1: 652b649ebaa793f80df2381948dc60dceecbd0ec
sha256: 7543c361813f1960e040008d0a5263ed0e52accc1e1ef4a0df25ceccac6a42f7
sha512: 62e5501a04643a317866218b366992f42550fce9bf874acb16df79c5aa8cb834e8e9b5f0fb6954a5d29c6d22ff4cf94bd108f3f5b9ba52513abf23af7ac0c47d
ssdeep: 49152:qkjrl341RiJbrKWOPl93Ul4MdvGjnbSjpN5h:qkj+m1Z6lqLdAbUbD
type: MS-DOS executable, MZ for MS-DOS

Version Info:

FileVersion: 4.4.9.8
ProductVersion: 4.4.9.8
Translation: 0x0809 0x04b0

Trojan-Banker.Win32.ClipBanker.gyp also known as:

MicroWorld-eScanTrojan.GenericKD.42054085
CMCVirus.Win32.Sality!O
McAfeeGenericRXIX-KX!94472427C06F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00559a571 )
AlibabaPacked:Win32/Autoit.cb8625f7
K7GWTrojan ( 00559a571 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.32515.Pnuaaai@2Dpi
ESET-NOD32a variant of Win32/Packed.Autoit.NBE suspicious
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.ClipBanker.gyp
BitDefenderTrojan.GenericKD.42054085
Endgamemalicious (high confidence)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.94472427c06fe8a5
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
FortinetAutoIt/Packed.KY!tr
Antiy-AVLTrojan/Win32.Scar
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-Banker.Win32.ClipBanker.gyp
Acronissuspicious
VBA32Trojan.Occamy
Ad-AwareTrojan.GenericKD.42054085
MalwarebytesTrojan.Qulab
TrendMicro-HouseCallTROJ_GEN.R002H06KO19
MAXmalware (ai score=89)
MaxSecureTrojan.Malware.300983.susgen
GDataTrojan.GenericKD.42054085
AVGFileRepMetagen [Malware]
Cybereasonmalicious.ebaa79
AvastFileRepMetagen [Malware]
Qihoo-360Win32/Trojan.add

How to remove Trojan-Banker.Win32.ClipBanker.gyp?

Trojan-Banker.Win32.ClipBanker.gyp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment